CVE-2019-0541: high-severity vulnerability in Microsoft Office
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
A flaw in Microsoft's web rendering engine (MSHTML) allows attackers to execute malicious code on your computer when you open a specially crafted document or visit a malicious website. This affects multiple Microsoft products including Office, Excel, Word, and Internet Explorer.
MSHTML engine fails to properly validate input in web content, enabling remote code execution via crafted documents or web pages. Attack vector is network-based with low attack complexity; requires user interaction (opening document or visiting site). Successful exploitation grants arbitrary code execution in the context of the affected application.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.